Incorrect authorization in snipe-it - #VU145091

 

Incorrect authorization in snipe-it - #VU145091

Published: August 25, 2026


Vulnerability identifier: #VU145091
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify audit log entries for assets outside their FMCS visibility and disclose limited asset-related information.

The vulnerability exists due to improper access control in asset audit endpoints when handling audit requests for target assets. A remote user can send a request targeting an asset outside their authorized FMCS scope to modify audit log entries for assets outside their FMCS visibility and disclose limited asset-related information.

This applies to installations with FMCS enabled, and exploitation requires knowledge of the target asset identifier such as an id, asset tag, or serial depending on the endpoint.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins